PT-2004-1643 · Sap · Sap Business Objects Web Intelligence
Published
2004-12-31
·
Updated
2017-07-11
·
CVE-2004-0533
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Business Objects WebIntelligence versions 2.7.0 through 2.7.4
Description
The issue allows remote authenticated users to delete arbitrary files on the server by sending a crafted delete request using the InfoView web client, due to the software only enforcing access controls on the client.
Recommendations
For versions 2.7.0 through 2.7.4, consider restricting access to the delete request functionality in the InfoView web client until a patch is available. As a temporary workaround, limit the privileges of authenticated users to prevent them from deleting arbitrary files on the server.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sap Business Objects Web Intelligence